1

Incident Analyst Jobs in Raleigh, NC (NOW HIRING)

Senior Incident Manager

Cary, NC · On-site

$100 - $140/hr

Experience facilitating postmortems and applying root cause analysis frameworks to drive durable ... Experience with incident tooling (e.g., PagerDuty, Slack automation, observability platforms)

Iteris is looking for a Traffic Incident Program Engineer to support the North Carolina DOT TIM ... Review an d analyze TIM performance data * Strategic planning * Arranging After Action Reviews (AAR ...

Iteris is looking for a Traffic Incident Program Engineer to support the North Carolina DOT TIM ... Review an d analyze TIM performance data * Strategic planning * Arranging After Action Reviews (AAR ...

next page

Showing results 1-20

Incident Analyst information

See Raleigh, NC salary details

$18

$37

$61

How much do incident analyst jobs pay per hour?

As of Aug 25, 2026, the average hourly pay for incident analyst in Raleigh, NC is $37.24, according to ZipRecruiter salary data. Most workers in this role earn between $28.03 and $42.31 per hour, depending on experience, location, and employer.

What is an incident analyst?

Incident Analysts are professionals responsible for identifying, investigating, and managing incidents that disrupt normal operations within an organization, particularly related to IT systems and cybersecurity. They monitor systems for unusual activity, assess the severity of incidents, and coordinate responses to mitigate risks and restore services. Incident Analysts also document incidents, analyze root causes, and recommend improvements to prevent future occurrences. Their work is essential for maintaining the security and reliability of an organization's technology infrastructure.

What does an incident analyst do?

An incident analyst works to investigate cybersecurity or computer network-related incidents. Your job duties in this career include working to diagnose issues related to each event. You usually document your efforts and report on your findings. Your employers then expect you to develop and implement strategies to handle (or avoid) similar incidents in the future. Your responsibilities could include working to monitor current networks/systems and examining security practices and procedures to find areas for operational improvement.

What are the key skills and qualifications needed to thrive as an incident analyst, and why are they important?

To thrive as an Incident Analyst, you need a solid understanding of IT systems, incident management processes, and analytical problem-solving, often supported by a degree in computer science or certifications like ITIL or CompTIA Security+. Familiarity with incident tracking systems, SIEM tools, and ticketing platforms is typically required. Strong communication, attention to detail, and the ability to remain calm under pressure are standout soft skills for this role. These skills ensure swift and effective response to incidents, minimizing business impact and maintaining organizational security.

How does an incident analyst typically interact with other IT teams during a major incident?

During a major incident, an Incident Analyst acts as a central point of coordination between various IT teams such as network operations, application support, and security. They facilitate communication, gather updates, and ensure that all teams have the information needed to resolve the issue efficiently. This role often involves organizing conference calls, documenting actions taken, and escalating problems when necessary. Effective collaboration and clear communication are critical skills, as the Incident Analyst helps drive the incident toward resolution while minimizing business impact.

What is the difference between Incident Analyst vs Security Analyst?

AspectIncident AnalystSecurity Analyst
Required CredentialsCertifications like CompTIA Security+, incident response trainingCertifications like CISSP, Security+, CEH
Work EnvironmentIT teams, incident response centers, corporate environmentsSecurity operations centers, IT security teams, corporate and government sectors
Employer & Industry UsageUsed across industries for incident management and responsePrimarily in cybersecurity, finance, government, and tech sectors
Common Search & ComparisonOften compared for incident handling rolesCompared for cybersecurity and threat management roles

While both Incident Analysts and Security Analysts work within IT and security environments, Incident Analysts focus on managing and responding to specific incidents, such as system outages or data breaches. Security Analysts have a broader role in protecting organizational assets from cyber threats, often requiring advanced security certifications. Understanding these differences helps organizations assign the right roles for effective incident response and security management.

Is incident response entry level?

Incident Analyst roles can be entry-level or require experience depending on the organization. Entry-level positions typically focus on monitoring security alerts and supporting incident investigations, often requiring basic knowledge of cybersecurity tools and concepts. More advanced roles may require certifications like CompTIA Security+ or CISSP and prior experience in security operations.

What do you need to be an incident analyst?

To become an incident analyst, candidates typically need a bachelor's degree in cybersecurity, information technology, or a related field. Strong analytical skills, knowledge of security tools and incident response procedures, and experience with data analysis or security monitoring are important. Certifications like CISSP or GIAC can also enhance qualifications.

What are popular job titles related to Incident Analyst jobs in Raleigh, NC?

For Incident Analyst jobs in Raleigh, NC, the most frequently searched job titles are:

What job categories do people searching Incident Analyst jobs in Raleigh, NC look for?

The top searched job categories for Incident Analyst jobs in Raleigh, NC are:

Infographic showing various Incident Analyst job openings in Raleigh, NC as of August 2026, with employment types broken down into 1% As Needed, 89% Full Time, 8% Part Time, and 2% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $77,462 per year, or $37.2 per hour.

$140K - $188K/yr

Full-time

Posted 16 days ago


First Citizens Bank rating

7.4

Company rating: 7.4 out of 10

Based on 106 frontline employees who took The Breakroom Quiz

106th of 172 rated banks


Job description

Overview

This position supports the Bank’s Information Security and Cyber Threat management programs at the highest level of complexity and expertise. Leads the analysis and mitigation of threats identified within the Bank’s networks and systems. Ensures that team reporting is timely, accurate, and escalated as necessary to provide actionable intelligence for cyber defense efforts. Develops process improvements and technical solutions that address the identified gaps or deficiencies. Drives the defense of the organization’s information security and technological architecture through expert consultation and threat mitigation. Serves as a resource to team members and management on security threats, industry trends, and other relevant intelligence. Leads projects within the work group and resolves escalated, high-risk issues.


Responsibilities & Qualifications

Duties & Responsibilities:


Security Review - Serves as an escalation point for complex threats and analytics issues from other members in the work group. Leads the review of security incidents, system alerts, audit events, and other threats against the Bank’s networks and systems. Detects anomalies, malware infections, and intrusion attempts. Identifies, recommends, and directs the mitigation strategy for identified threats.
Business Support - Serves as an expert analytics resource for associate team, management, and business units. Supports the design and implementation of new security strategies, products, services, processes, and technologies in response to changes in the security threat landscape. Enables the defense of the organization’s information security and technological architecture through a number of operational and technical tasks. Ensures all cyber security monitoring systems are online and fully operational as well as ensuring compliance with all security policies and standards. Assesses whether team members are trained on the latest cyber-security trends, threats, and applicable technologies.
Analysis - Analyzes data from various operating systems, databases, and applications within the Bank as well as external sources. Compiles and interprets data to proactively search for threats. May assist with data management efforts.
Reporting - Produces reports that document investigation and security incidents as well as the results of analysis. Provides analytics and reporting that facilitates actionable cyber-intelligence within daily operations. Conveys information to the appropriate parties, which includes both internal and external partners.

Position Specific Skills:


Knowledge of security event log analytics and at least two of the following technologies: Firewall, Web-Proxy, IDS/IPS, Anti-Virus/Anti-Malware, Anti-Phishing, Malicious Web Site reporting or take-down
Knowledge of at least three of the following: Insider Threats, Advanced Persistent Threats, Malware Analysis, Exploit techniques, Regular Expressions, SEIM Tuning , Alarm and Signature Creation
Knowledge of Information Technologies with a focus in two or more of the following areas: operating systems, networking, computer programming, web development or database administration
Understanding of Internet Protocol Suite networking, including routers, switches, public and private networks, internet protocol security, and virtual private networks
Knowledge of Packet Capture and analysis
Knowledge of systems administration and analysis as well as risk management standards, procedures, and practices

Qualifications:


Minimum Required Education and Experience: Bachelor's Degree and 8 years' experience.

OR

High School Diploma or GED/Equivalent and 12 years' experience in Information Security.


Preferred Education:
Preferred Area of Study:
Preferred Area of Experience:
Required Licenses or Certifications:
Preferred Licenses or Certifications:

  • Experience with all aspects of Incident response including stakeholder management. 
  • 2+ years of Threat Hunting experience.
  • Familiarity with MITRE ATT&CK and its application to countermeasure creation is a plus. 
  • Experience analyzing/dispositioning and escalating security events (systems, application, network, authentication email events) 
  • Experience translating threat actor techniques to building mitigations across a variety of security technologies. This could take the form of Yara, Sigma or Regular Expressions. 
  • Ability to define security requirements and drive project deliverables. 
  • Ability to keep track of multiple incidents and ensure responses are provided in a timely fashion. 
  • Experience responding to cloud-related incidents in Azure, AWS and Google cloud.
  • Cloud administrative experience preferred.
  • Cyber Incident Response experience – 3+ years required in which your primary job was an Incident Response role.
  • This role requires participation in the afterhours on call rotation. Rotations will cycle on a weekly basis.

Additional Information

The base pay for this position is generally between $140,000 and $188,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.

This job posting is expected to remain active for 45 days from the initial posting date listed above.  If it is necessary to extend this deadline, the posting will remain active as appropriate.  Job postings may come down early due to business need or a high volume of applicants

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Qualifications:

The base pay for this position is generally between $140,000 and $188,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.

This job posting is expected to remain active for 45 days from the initial posting date listed above.  If it is necessary to extend this deadline, the posting will remain active as appropriate.  Job postings may come down early due to business need or a high volume of applicants

Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at https://jobs.firstcitizens.com/benefits.

Education:UNAVAILABLEEmployment Type: FULL_TIME

What First Citizens Bank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom